🔥 Trending CVEs - Last 90 Days

4,484 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,080
Total CVEs Published
990
Critical Severity
3,494
High Severity
⚠️
Critical Alert
990 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-71021 7.5

Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the serverName parameter that allows attackers to crash the ...

📅 57 days ago • Jan 14, 2026
CVE-2026-21889 7.5

CVE-2026-21889 is an improper access control vulnerability in Weblate where screenshot images were served directly by the HTTP server without authenti...

📅 57 days ago • Jan 14, 2026
CVE-2026-22240 7.5

This vulnerability allows unauthenticated attackers to retrieve plaintext passwords for all users, including administrators, via exposed APIs in BLUVO...

📅 58 days ago • Jan 14, 2026
CVE-2025-9142 7.5

This vulnerability allows a local user on a Windows system to manipulate the Harmony SASE client to write or delete files outside its intended certifi...

📅 58 days ago • Jan 14, 2026
CVE-2025-14770 7.5

This SQL injection vulnerability in the WordPress Shipping Rate By Cities plugin allows unauthenticated attackers to inject malicious SQL queries thro...

📅 58 days ago • Jan 14, 2026
CVE-2022-50932 7.5

Kyocera Command Center RX ECOSYS M2035dn has a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files ...

📅 58 days ago • Jan 13, 2026
CVE-2025-68698 7.5

Jervis versions before 2.2 use vulnerable PKCS1Encoding for RSA encryption, making them susceptible to Bleichenbacher padding oracle attacks. This cou...

📅 58 days ago • Jan 13, 2026
CVE-2025-68701 7.5

Jervis versions before 2.2 use deterministic AES initialization vectors derived from passphrases, making encrypted data vulnerable to cryptographic at...

📅 58 days ago • Jan 13, 2026
CVE-2025-68702 7.5

Jervis versions before 2.2 incorrectly use 32-character padding instead of 64-character padding for SHA-256 hashes, which could lead to hash collision...

📅 58 days ago • Jan 13, 2026
CVE-2025-68703 7.5

This vulnerability in Jervis (a library for Jenkins pipeline scripts) uses a weak key derivation method where the same password always produces the sa...

📅 58 days ago • Jan 13, 2026
CVE-2025-68704 7.5

Jervis versions before 2.2 use java.util.Random() for timing attack mitigation, which is not cryptographically secure. This vulnerability could allow ...

📅 58 days ago • Jan 13, 2026
CVE-2025-68931 7.5

CVE-2025-68931 is a cryptographic vulnerability in Jervis library versions before 2.2 where AES/CBC/PKCS5Padding lacks authentication, enabling paddin...

📅 58 days ago • Jan 13, 2026
CVE-2026-21226 7.5

This vulnerability in Azure Core shared client library for Python allows deserialization of untrusted data, enabling an authorized attacker to execute...

📅 58 days ago • Jan 13, 2026
CVE-2026-20965 7.5

This vulnerability in Windows Admin Center allows an authorized attacker to bypass cryptographic signature verification, enabling local privilege esca...

📅 58 days ago • Jan 13, 2026
CVE-2026-20934 7.5

A race condition vulnerability in Windows SMB Server allows authenticated attackers to execute code with elevated privileges over the network. This af...

📅 58 days ago • Jan 13, 2026
CVE-2026-20926 7.5

A race condition vulnerability in Windows SMB Server allows authenticated attackers to escalate privileges over the network by exploiting improper syn...

📅 58 days ago • Jan 13, 2026
CVE-2026-20929 7.5

This vulnerability in Windows HTTP.sys allows authenticated attackers to escalate privileges over a network connection. It affects Windows systems run...

📅 58 days ago • Jan 13, 2026
CVE-2026-20919 7.5

A race condition vulnerability in Windows SMB Server allows authenticated attackers to elevate privileges over the network. This affects Windows syste...

📅 58 days ago • Jan 13, 2026
CVE-2026-20921 7.5

A race condition vulnerability in Windows SMB Server allows authenticated attackers to elevate privileges over the network. This affects Windows syste...

📅 58 days ago • Jan 13, 2026
CVE-2026-20875 7.5

A null pointer dereference vulnerability in Windows LSASS allows attackers to cause a denial of service by crashing the service. This affects Windows ...

📅 58 days ago • Jan 13, 2026
CVE-2026-20854 7.5

This CVE describes a use-after-free vulnerability in Windows LSASS that allows authenticated attackers to execute arbitrary code remotely over a netwo...

📅 58 days ago • Jan 13, 2026
CVE-2026-20848 7.5

A race condition vulnerability in Windows SMB Server allows authenticated attackers to escalate privileges over the network. This affects Windows syst...

📅 58 days ago • Jan 13, 2026
CVE-2026-20849 7.5

This Windows Kerberos vulnerability allows authenticated attackers to elevate privileges over a network by exploiting reliance on untrusted inputs in ...

📅 58 days ago • Jan 13, 2026
CVE-2026-0386 7.5

This vulnerability allows an unauthorized attacker on an adjacent network to execute arbitrary code on Windows systems running vulnerable Windows Depl...

📅 58 days ago • Jan 13, 2026
CVE-2025-37165 7.5

A vulnerability in HPE Instant On Access Points router mode configuration exposes internal network configuration details through packet inspection. Ma...

📅 58 days ago • Jan 13, 2026
CVE-2025-37166 7.5

A vulnerability in HPE Networking Instant On Access Points allows attackers to send specially crafted packets that cause devices to become unresponsiv...

📅 58 days ago • Jan 13, 2026
CVE-2025-25652 7.5

This directory traversal vulnerability in Eptura Archibus allows attackers to access files outside the intended directory through the 'Run script' and...

📅 58 days ago • Jan 13, 2026
CVE-2025-46685 7.5

Dell SupportAssist OS Recovery versions before 5.5.15.1 create temporary files with insecure permissions, allowing local low-privileged attackers to m...

📅 58 days ago • Jan 13, 2026
CVE-2026-0889 7.5

A denial-of-service vulnerability in Firefox and Thunderbird's DOM Service Workers component allows attackers to crash the browser or email client. Th...

📅 59 days ago • Jan 13, 2026
CVE-2025-40944 7.5

This vulnerability affects multiple Siemens SIMATIC industrial control system modules. An attacker can send a specially crafted S7 protocol disconnect...

📅 59 days ago • Jan 13, 2026
CVE-2026-22776 7.5

A Denial of Service vulnerability exists in cpp-httplib where compressed HTTP request bodies are not properly limited after decompression. Attackers c...

📅 59 days ago • Jan 12, 2026
CVE-2026-22200 7.5

This vulnerability allows remote attackers to read arbitrary files from the osTicket server filesystem by crafting malicious HTML in ticket content an...

📅 59 days ago • Jan 12, 2026
CVE-2025-69271 7.5

CVE-2025-69271 is an insufficient credential protection vulnerability in Broadcom DX NetOps Spectrum that allows attackers to sniff network traffic an...

📅 60 days ago • Jan 12, 2026
CVE-2025-69272 7.5

Broadcom DX NetOps Spectrum transmits sensitive information without encryption, allowing attackers on the same network to intercept credentials, confi...

📅 60 days ago • Jan 12, 2026
CVE-2025-69273 7.5

This vulnerability allows attackers to bypass authentication mechanisms in Broadcom DX NetOps Spectrum, potentially gaining unauthorized access to net...

📅 60 days ago • Jan 12, 2026
CVE-2025-52435 7.5

This vulnerability in Apache NimBLE allows an attacker to downgrade encrypted Bluetooth Low Energy connections to unencrypted state after a Pause Encr...

📅 62 days ago • Jan 10, 2026
CVE-2025-53477 7.5

A NULL pointer dereference vulnerability in Apache NimBLE's Bluetooth stack occurs when HCI connection completion or command transmission buffers lack...

📅 62 days ago • Jan 10, 2026
CVE-2026-22777 7.5

ComfyUI-Manager extension versions before 3.39.2 and 4.0.5 contain an injection vulnerability where attackers can manipulate HTTP query parameters to ...

📅 62 days ago • Jan 10, 2026
CVE-2026-22698 7.5

A critical vulnerability in RustCrypto's SM2 Public Key Encryption implementation generates ephemeral nonces with only 32 bits of entropy instead of t...

📅 62 days ago • Jan 10, 2026
CVE-2026-22699 7.5

This vulnerability in RustCrypto's elliptic-curves library allows attackers to cause denial-of-service by sending specially crafted SM2 encrypted mess...

📅 62 days ago • Jan 10, 2026
CVE-2026-22700 7.5

A denial-of-service vulnerability exists in RustCrypto's SM2 public-key encryption implementation where untrusted ciphertext can trigger bounds-check ...

📅 62 days ago • Jan 10, 2026
CVE-2025-66744 7.5

This vulnerability in Yonyou YonBIP allows attackers to bypass normal directory restrictions via path traversal in the LoginWithV8 interface, potentia...

📅 62 days ago • Jan 9, 2026
CVE-2025-67133 7.5

A vulnerability in Hero Motocorp Vida V1 Pro 2.0.7 allows local attackers to cause denial of service via the Bluetooth Low Energy (BLE) component. Thi...

📅 62 days ago • Jan 9, 2026
CVE-2025-56225 7.5

FluidSynth versions 2.4.6 and earlier contain a null pointer dereference vulnerability in fluid_synth_monopoly.c that can be triggered by loading a sp...

📅 62 days ago • Jan 9, 2026
CVE-2025-66049 7.5

Vivotek IP7137 cameras with firmware version 0200a allow unauthenticated access to live RTSP video feeds on port 8554. This affects all users of these...

📅 63 days ago • Jan 9, 2026
CVE-2025-64092 7.5

This CVE describes an unauthenticated SQL injection vulnerability in Zenitel products that allows attackers to inject SQL queries via GET request para...

📅 63 days ago • Jan 9, 2026
CVE-2025-15464 7.5

This vulnerability allows external applications to bypass security controls and directly launch Gmail with inbox access by exploiting an exported Acti...

📅 63 days ago • Jan 8, 2026
CVE-2026-22235 7.5

This vulnerability in OPEXUS eComplaint allows unauthenticated attackers to download sensitive files by guessing predictable charge numbers. It affect...

📅 63 days ago • Jan 8, 2026
CVE-2026-22521 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the G5Theme Handmade Framework WordPress plugin. Attackers can include arbitrary local ...

📅 63 days ago • Jan 8, 2026
CVE-2025-50334 7.5

A vulnerability in Technitium DNS Server v13.5 allows remote attackers to trigger a denial of service condition by exploiting the rate-limiting compon...

📅 63 days ago • Jan 8, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free